Every managed IT provider (including us) will tell you they’re great. We’ll talk about “proactive support” and “strategic partnerships” and all the things you want to hear. But when something important breaks at 3pm on a Friday, how do you know you’ve got someone on your side until it’s fixed?
We’ve been running an MSP on the Gold Coast since 2015, and through our peer group programs, industry events, and conversations with businesses who’ve switched to us from other providers, we’ve seen some patterns. And according to our marketing fellow Gio, it’s important that we write about them. So here’s what we think you should actually look for.

They solve problems, not just close tickets
This is the big one, and it’s a hard thing to spot from the outside.
A lot of IT providers measure their technicians on two things: billable hours and tickets closed. On paper, that sounds reasonable. But it creates a weird incentive where tickets get closed before they’re actually resolved, and time gets logged for the sake of logging time rather than making real progress.
A technically skilled technician at an average provider might sink four or five hours into a problem that doesn’t need that much attention, go down a rabbit hole, and never step back to ask: is this actually helping the customer?
Good providers measure outcomes. Their technicians understand the business context they’re working in. They ask themselves: what does this problem mean for the customer? Is there a better way they could be doing this? Is this issue coming up over and over again, suggesting something else needs fixing?
🚩 Red flag
Your technician can’t tell you what your business actually does. They close tickets without asking whether the underlying issue has been addressed.
✅ Green flag
Your provider’s team understands your business context, spots recurring issues, and fixes root causes rather than just symptoms.
They run their business like a business
A lot of managed IT providers were started by technical people. Someone who was great at fixing computers got more clients than they could handle, hired some help, and gradually evolved from break-fix into managed services. There’s nothing wrong with that origin story, it’s how we started too – but without deliberate effort, the business stays technical-focused and never develops the operational maturity that businesses need from their IT partner.
We run our business using the Entrepreneurial Operating System (EOS), which gives us a structured way to identify issues, set goals, and make sure things actually get done. Every week, the team sits down, reviews what was committed to, flags new issues, and generates clear action items.
The specific framework doesn’t matter as much as the fact that one exists. If your IT provider can’t tell you what their process is for handling operational or process issues beyond “we’ll log a ticket,” that tells you something.
Good providers benchmark themselves against others. We do this through ConnectWise Evolve, a peer group program where MSPs compare operations, share what’s working, and hold each other accountable.
Similar programs exist through Kaseya, Pax8, and TSP Partners. An IT provider that operates in isolation tends to stagnate.
They didn’t fight the cloud, and they’re not fighting AI
This one’s a litmus test for whether your provider puts your interests first or theirs.
Back in the early-to-mid 2010s, a lot of IT providers clung to on-premise Exchange servers and Windows Small Business Server. They made good money selling hardware, maintaining servers, and charging for break-fix work when things went wrong. Back then, an earlier version of Microsoft 365, called Office 365 Business Essentials, was available for about $6 per user per month and did everything those servers did, with better redundancy, mobile access, and collaboration tools like SharePoint that were previously out of reach for small businesses.
But many providers gatekept that transition because it threatened their business model. They had 20 or 30 Exchange clients generating substantial revenue, and they weren’t keen to swap that for a few dollars of margin on cloud licenses.
The customers who stayed with those providers missed years of productivity gains. The ones who found providers aligned with their interests got ahead.
🚩 Then (2014)
“The cloud isn’t secure enough. Your data is safer on a local server we manage.” Meanwhile, Office 365 Business Essentials was $6/user/month with better uptime than any on-prem server.
🚩 Now (2026)
“AI isn’t reliable enough. It hallucinates and makes mistakes.” Meanwhile, providers who’ve embraced it are resolving issues faster and delivering better service.
The same pattern is playing out right now with AI. There are plenty of IT providers who dismiss AI because it makes mistakes, hallucinates, or raises ethical concerns. Some of those concerns are valid. But providers who refuse to explore how AI can improve their operations and their customers’ businesses will get left behind, exactly the way the anti-cloud providers did a decade ago.
Ask your IT provider what they’re doing with AI. Not just whether they’ve heard of Copilot, but what they’ve actually implemented. Are they using it to improve response times? To ground their support in your specific environment? If the answer is “we’re keeping an eye on it,” they’re already behind.
They can do security at scale (not just for one company)
This is something businesses don’t always think about when choosing an IT provider, but it matters a lot.
A single enterprise that wants to roll out a new security measure, like phishing-resistant MFA or strict conditional access policies, has one rollout and one decision-making board to convince. An MSP doing the same thing needs to do it across 100, 200, or in our case, around 300 to 350 customer tenants.
300–350
customer tenants we deploy security policies across simultaneously
When attacks that could bypass traditional MFA emerged (through tools like Evilginx that steal session tokens), every provider had to respond. The good ones automated the rollout. We went into the sign-in logs across all our tenants, identified which countries each user was legitimately logging in from, and deployed conditional access policies locking things down. We also built an automated process for travelling users, so they could be temporarily excluded from country restrictions with proper controls, then put back on the full policy when their trip ended.
Providers who did this manually? It would have consumed their entire year in back-and-forth meetings and configuration work for just a fraction of their clients. The rest would have been left exposed.
🚩 Red flag
Your provider can’t explain how they deploy security changes across all their customers. They’re probably doing it manually, and you may not be at the front of the queue.
✅ Green flag
Your provider automates security rollouts across their entire customer base and has processes for exceptions like travelling users.
They’re transparent about everything
This sounds basic, but a surprising number of IT providers operate as a black box. You pay your monthly invoice, things mostly work, and you have no idea what they’re actually doing.
Transparency checklist: What a good provider gives you
- ☐ A clear SLA with defined response and resolution times
- ☐ Customer access to the ticketing system so you can see the status of every request
- ☐ Monthly reporting that shows what was done, not just that things are “fine”
- ☐ Transparent pricing with no surprise charges
- ☐ Regular account reviews (quarterly at minimum) to discuss your roadmap, security posture, and upcoming changes
The relationship should feel like a partnership, not a transaction. If your current provider makes you feel like you’re bothering them every time you call, something is off.
They have an answer for compliance
This has changed a lot in the last few years. It used to be that only large enterprises worried about cybersecurity compliance frameworks. Now, even small businesses on the Gold Coast are being asked about their compliance posture when submitting tenders or signing contracts with larger organisations.

ISO 27001, Essential Eight, SMB1001, NIST, CIS Controls – these frameworks are increasingly becoming table stakes, not differentiators. A good IT provider should be able to help you understand which frameworks are relevant to your business, assess where you stand, and build a practical roadmap to get you there.
We’re the first Gold Coast-based MSP certified to ISO 27001, 9001, and 14001, because we believe if we’re going to advise customers on compliance, we should practice what we preach.
What to actually do with this
If you’re evaluating IT providers (or wondering whether your current one is the right fit), here are the questions worth asking:
7 questions to ask your IT provider
- How do you measure your technicians’ performance? If the answer is only about tickets closed and hours logged, that tells you their priorities.
- What framework do you use to run your business? EOS, Scaling Up, something proprietary – doesn’t matter. The absence of one matters.
- What peer groups or industry programs are you part of? Isolation breeds stagnation.
- What are you doing with AI right now? Not just your plans, what are you trying now.
- How do you deploy security changes across your customer base? The answer reveals whether they can handle scale.
- Can I see an example of your monthly reporting? If they hesitate, that’s your answer.
- What compliance certifications do you hold? And what frameworks can you help me with?
The bottom line
A good managed IT provider doesn’t just keep the lights on. They should be making your business more productive, more secure, and better positioned for what’s coming next, whether that’s AI, new compliance requirements, or whatever the next industry shift turns out to be.
The bad ones will tell you everything is fine while you fall behind. The good ones will push you forward, sometimes uncomfortably, because that’s what a good partner does.
If you’re not sure where your current provider sits, have a conversation with us.